On June 5th, 2014, a number of vulnerabilities in OpenSSL were disclosed (see https://www.openssl.org/news/secadv_20140605.txt). One of those, the CCS Injection Vulnerability, affects OpenVPN. This page discusses the consequences for OpenVPN users.
## What does the CCS Injection Vulnerability mean?
-
In short: if both the client and the server are running a vulnerable version of OpenSSL, an active attacker with a man-in-the-middle position can trick OpenSSL to use keys known to the attacker. This means the attacker can read and even manipulate everything on the TLS connection. In the OpenVPN case, that includes the traffic protection keys for your VPN data, and thus your VPN data. For more information, visit the CCS Injection Vulnerability page at http://ccsinjection.lepidum.co.jp/ or check the CVE at [Mitre](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224).
+
In short: if both the client and the server are running a vulnerable version of OpenSSL, an active attacker with a man-in-the-middle position can trick OpenSSL to use keys known to the attacker. This means the attacker can read and even manipulate everything on the TLS connection. In the OpenVPN case, that includes the traffic protection keys for your VPN data, and thus your VPN data. For more information, visit the CCS Injection Vulnerability page at http://ccsinjection.lepidum.co.jp/ or check the CVE at [Mitre](https://www.cve.org/CVERecord?id=CVE-2014-0224).
Use of [TLS auth](/PageS/Hardening) prevents this vulnerability from being exploited.
## What should I do?
* Update your OpenSSL and restart OpenVPN (and any other daemons using it).
-
* If you're using the OpenVPN Windows installer upgrade to the [latest OpenVPN release](http://openvpn.net/index.php/download/community-downloads.html).
+
* If you're using the OpenVPN Windows installer upgrade to the [latest OpenVPN release](https://openvpn.net/index.php/download/community-downloads.html).
* Use TLS-auth as an extra layer of protection (see [Hardening](/Pages/Hardening)).
## Do I need to create new private keys and certificates?